Privacy Policy
In accordance with GDPR (EU) 2016/679 — Last updated: April 2026
1. Controller (Art. 4 No. 7 GDPR)
Responsible for data processing on this website:
Isam Al-Ani · Core IndustryMax Schwarze Weg 27A, 46236 BottropE-Mail: info@coreindustry.deTel.: +49 2041 3894257
2. Overview of data processed
Data categories processed:
- Master data (name, company name)
- Contact data (email address, phone number)
- Content data (messages from forms, support chat)
- Usage data (pages visited, dwell time, click paths)
- Meta/communication data (IP address, browser, device, timestamp)
- Newsletter data (email address on sign-up)
- For AI telephony: call metadata, AI transcriptions (via third-party provider)
Purposes: Website operation, processing enquiries, contract fulfilment, customer support, invoicing, web analytics (consent only).
3. Legal bases (Art. 6 GDPR)
- Art. 6 para. 1 lit. a GDPR — Consent (e.g. analytics cookies, newsletter)
- Art. 6 para. 1 lit. b GDPR — Contract performance (all software projects, AI telephony)
- Art. 6 para. 1 lit. c GDPR — Legal obligation (invoice retention, accounting)
- Art. 6 para. 1 lit. f GDPR — Legitimate interest (server logs, security, anti-spam)
4. Data collection when visiting the website
Server log files (Netlify)
When you visit our website, your browser automatically transmits information to the web server (Netlify, Inc.): IP address, browser type/version, operating system, referrer URL, requested page and time. This data is technically required to deliver the website. Legal basis: Art. 6 para. 1 lit. f GDPR. Retention: max. 30 days.
5. Cookies and cookie consent
This website uses cookies. Technically necessary cookies do not require consent. All other cookies are only loaded after your explicit consent via the cookie banner.
Necessary cookies (always active)
| Name | Purpose | Duration |
|---|---|---|
| portal_session | Admin/client portal authentication | Session |
| ci_cookie_consent | Stores your cookie consent | 1 year |
| ci_support_session | Support chat session ID (localStorage) | Persistent (local) |
Analytics cookies (consent only)
| Name | Provider | Duration |
|---|---|---|
| _ga | Google Analytics | 2 years |
| _ga_* | Google Analytics | 2 years |
| _clsk, _clck | Microsoft Clarity | 1 year / session |
You may withdraw your consent at any time by clearing your browser's localStorage or contacting us at info@coreindustry.de.
6. Google Analytics 4 (consent only)
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics sets cookies (_ga, _ga_*) and transfers usage data to Google servers (potentially in the USA, secured by the EU-US Data Privacy Framework and Standard Contractual Clauses under Art. 46 GDPR). IP anonymisation is enabled.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent). Loaded only after consent via cookie banner.
Permanent opt-out: tools.google.com/dlpage/gaoptout
7. Microsoft Clarity (consent only)
This website uses Microsoft Clarity, a behavioural analytics service by Microsoft Corporation. We use Clarity to improve website usability — no advertising, no profiling, no cross-site tracking.
Clarity collects anonymised usage data (click/scroll behaviour, session recordings in anonymised form) on Microsoft servers (USA). Sensitive input fields are automatically masked.
Tracked conversion events
lead_saved— Lead submission in Corie chat completedcontact_form_submitted— Contact form submittednewsletter_signup— Newsletter signup successfulsupport_requested— Support request escalated via Coriecorie_chat_opened— Corie chat opened for first time in sessioncorie_image_requested— Design preview requested
Legal basis: Art. 6 para. 1 lit. a GDPR (consent). Retention: 13 months (Microsoft standard). Data processing agreement concluded under Art. 28 GDPR.
Microsoft privacy policy: privacy.microsoft.com
8. Contact (form, email, phone, WhatsApp)
When you contact us, the transmitted data (name, email, message content) is stored to process your enquiry. Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 6 para. 1 lit. f GDPR.
WhatsApp: When contacting us via WhatsApp, Meta Platforms Ireland Ltd.'s privacy policy applies. Do not transmit sensitive data via WhatsApp.
Retention: Enquiries are deleted after full resolution, unless statutory retention obligations apply (10 years).
9. Live support chat
When you use the chat, the following data is processed and stored in Google Firebase (Firestore):
- Your self-provided name (free text)
- Message content of the conversation
- Message timestamps
- The page viewed at the start of the chat
- A randomly generated session ID (UUID, stored locally in browser)
The IP address is stored as a SHA-256 hash for spam prevention for max. 24 hours and then automatically deleted.
Legal basis: Art. 6 para. 1 lit. b and f GDPR.
Chat histories are automatically deleted after 90 days.
10. Newsletter
Your email address is stored in Google Firebase (Firestore) upon sign-up. Legal basis: Art. 6 para. 1 lit. a GDPR (consent).
Unsubscribe: You can unsubscribe at any time by email to info@coreindustry.de. Your data will be deleted immediately.
11. AI phone assistant (service)
Core Industry offers AI-powered phone assistants for businesses. Data processed:
- Call metadata (timestamp, phone number, call duration)
- AI-generated transcriptions of call content
- Appointment data (name, requested date)
- Transfer information (when handed over to staff)
Callers are informed at the start of the call that they are speaking to an AI assistant. Core Industry acts as data processor (Art. 28 GDPR).
12. Corie AI assistant (website chatbot)
Messages you send to Corie are forwarded to the OpenRouter API (OpenRouter, Inc., San Francisco, CA, USA) for processing. OpenRouter provides multiple AI language models from various providers, including Google Gemini 2.0 Flash and others. Core Industry automatically selects the available best-performing model.
No conversation content is stored permanently. IP addresses are stored only as SHA-256 hashes for rate limiting, for a maximum of 24 hours, then automatically deleted. The usage limit is 20 messages per IP address per day.
Corie responses are purely informational and do not constitute legally binding offers or professional advice.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in automated initial information). Data transfer to the USA: secured by Standard Contractual Clauses (SCC) under Art. 46 GDPR and the EU-US Data Privacy Framework.
13. Fonts
This website uses fonts that are downloaded during the build process via Next.js and served directly from our web server (Netlify). No data is transmitted to Google servers when the page is loaded.
14. Hosting (Netlify)
This website is hosted by Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA. Server logs are processed on Netlify servers. Data transfer to the USA is secured by Standard Contractual Clauses (Art. 46 GDPR).
Netlify privacy policy: netlify.com/privacy
15. Google Firebase (database, auth, storage)
This website uses Google Firebase (Google Ireland Limited, Dublin) for:
- Firebase Authentication: Authentication of admin and client accounts
- Cloud Firestore: Storage of client profiles, projects, contracts, invoices, newsletter addresses, support chat histories, usage quotas
- Firebase Storage: Storage of blog images (publicly accessible)
Secured by the EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46 GDPR).
Firebase privacy policy: firebase.google.com/support/privacy
16. External services (social media, WhatsApp)
Meta Platforms Ireland Ltd. (WhatsApp, Instagram)
Merrion Road, Dublin 4, Ireland. When contacting us via WhatsApp/Instagram, Meta's privacy policy applies. Meta privacy policy
LinkedIn Ireland Unlimited Company
Wilton Plaza, Dublin 2, Ireland. LinkedIn privacy policy
17. Your rights (Art. 15–22 GDPR)
- Right of access (Art. 15) — What data we hold about you
- Right to rectification (Art. 16) — Correction of inaccurate data
- Right to erasure (Art. 17) — "Right to be forgotten"
- Restriction of processing (Art. 18)
- Data portability (Art. 20) — Data in machine-readable format
- Right to object (Art. 21) — Against processing based on legitimate interests
- Withdrawal of consent (Art. 7 para. 3) — At any time with future effect
Submit requests to: info@coreindustry.de
Right to lodge a complaint: Supervisory authority for NRW: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, Kavalleriestraße 2–4, 40213 Düsseldorf, ldi.nrw.de
18. Data security
Core Industry implements technical and organisational measures: SSL/TLS encryption (HTTPS), access restriction to authorised persons, hashed IP addresses for rate limiting, server-side validation of all inputs, regular security reviews.
Last updated: April 2026